OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102427

CRITICAL · CVSS 10 EPSS 0.79% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The OrdaSoft Joomla CCK extension prior to version 8.3.16 is vulnerable to unauthenticated remote code execution due to a lack of authentication and access control checks in the file upload process. Attackers can exploit this vulnerability by uploading a malicious file with a PHP extension, allowing them to execute arbitrary code on the server. Joomla administrators and users of the affected extension should prioritize immediate updates to mitigate this critical security risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102427
Severity
CRITICAL
CVSS
10
EPSS
0.79%

Original NVD Description

Joomla Extension - ordasoft.com - Unauthenticated Remote Code Execution in OrdaSoft Joomla CCK < 8.3.16 - site/uploader.php is reached through the component’s normal frontend routing (task=getContent), a task with no authentication or ACL check anywhere in the dispatch chain. The handler validates the uploaded file’s content with a real magic-byte MIME check, but the extension allow-list that would otherwise restrict the saved file’s extension was present in the source and commented out. The saved file’s extension was taken directly from the attacker-supplied filename with no validation, and the file was written to a path directly under the Joomla web root that is executed by the PHP handler. An image/PHP polyglot, a file whose header bytes satisfy the MIME check with PHP source appended after, passed the content check while carrying a .php extension of the attacker’s choosing.

Related CVEs

Other vulnerabilities affecting the same vendor(s)